EU Privacy Law EU/EEA

GDPR Data Protection Officer: When Mandatory, Role Definition, and Independence Requirements

When GDPR Articles 37 to 39 require a DPO, what the role must and must not do, independence rules, and how to appoint one without creating conflicts.

Regulation

GDPR, Articles 37 to 39

Max Penalty

EUR 10 million or 2% of global annual turnover for DPO failures

Enforcing Authority

National supervisory authorities, coordinated by the EDPB

Official Source

eur-lex.europa.eu

Executive Summary

  • Article 37 makes a DPO mandatory for public authorities, for core activities involving regular and systematic large-scale monitoring, and for large-scale special category processing.
  • The DPO must be independent: no instructions on how to do the job, no dismissal for doing it, and direct reporting to top management (Article 38(3)).
  • The DPO advises and monitors compliance but must not decide the purposes and means of processing; conflict-of-interest appointments are fined.
  • Belgium's DPA fined a company EUR 50,000 in 2020 for appointing its head of compliance, audit, and risk as DPO, a structural conflict of interest.
  • Groups can share one DPO, and external DPO services are permitted, as long as the officer is accessible and adequately resourced.

The data protection officer is the GDPR’s built-in internal supervisor: an expert who advises, monitors, and serves as the regulator’s contact point, protected from instruction and dismissal so the advice stays honest. Articles 37 to 39 govern when the role is mandatory, how it must be positioned, and what it does.

RegulationGDPR, Articles 37 to 39
Max penaltyEUR 10M or 2% of global turnover (Art. 83(4))
Enforcing authorityNational supervisory authorities, coordinated by the EDPB
Official textEUR-Lex CELEX 32016R0679

When you need one

Article 37(1) sets three triggers: public authorities (always), core activities requiring regular and systematic large-scale monitoring (behavioral advertising networks, telecoms, location-tracking apps), and core activities involving large-scale special category or criminal data (hospitals, insurers, background-check providers). “Core activities” means processing integral to the business, not payroll or ordinary IT support.

Member state law can extend the duty. Germany’s BDSG requires a DPO whenever at least 20 people are regularly involved in automated processing of personal data, which captures most German companies of any size. Even where not required, many organizations appoint one voluntarily; note that a voluntary DPO carries the same legal obligations as a mandatory one.

Independence is the hard part

Article 38 is where appointments fail. The DPO must be involved in all data protection issues in a timely manner, resourced adequately, given no instructions regarding the exercise of the tasks, protected from dismissal or penalty for performing them, and must report to the highest level of management. Article 38(6) allows other tasks only where they create no conflict of interest.

The conflict rule has teeth. The Belgian DPA fined a company EUR 50,000 in 2020 because its DPO simultaneously headed compliance, audit, and risk, meaning he would audit his own decisions. The same logic disqualifies CIOs, heads of HR, and marketing directors. The safe pattern: appoint someone who advises on processing but never decides it.

Qualifications and structure

The GDPR requires expert knowledge of data protection law and practices proportionate to the processing (Article 37(5)), but no specific certification. A group of companies may appoint a single DPO if easily reachable from each establishment, and external DPO services satisfy the regulation fully. What matters in an audit: the appointment is documented, contact details are published and filed with the authority, the DPO’s advice appears in DPIA records, and there is evidence management actually consulted the DPO before major decisions.

For the assessments the DPO advises on, see our DPIA guide. And since Article 37(7) requires your DPO contact to appear publicly, a free scan checks whether your privacy notice includes it.

Frequently Asked Questions

When is a DPO mandatory under GDPR?

In three cases under Article 37(1): you are a public authority or body, your core activities require regular and systematic monitoring of data subjects on a large scale, or your core activities involve large-scale processing of special category or criminal conviction data. Some national laws go further, such as Germany's threshold of 20 employees regularly processing personal data.

Can our compliance or IT manager also be the DPO?

Only if the other role does not determine the purposes and means of processing. Heads of IT, HR, marketing, or compliance functions that set processing policy are conflicted, and regulators have fined such appointments. A mid-level specialist or an external DPO avoids the problem.

What does a DPO actually do?

Article 39 lists the minimum tasks: inform and advise the organization, monitor GDPR compliance, advise on DPIAs, cooperate with the supervisory authority, and act as its contact point. The DPO advises; management decides and remains accountable.

Does the DPO have to be an employee?

No. Article 37(6) allows a service contract. External DPOs are common for mid-sized organizations. The requirements are the same: expertise, accessibility, independence, and no conflicting duties.

Do we have to publish the DPO's contact details?

Yes. Article 37(7) requires publishing the DPO's contact details and communicating them to the supervisory authority. A dedicated email address in the privacy notice is standard; the DPO's name is generally not required to be published.

Regulatory Crosswalk

UK GDPRLGPD (Encarregado)Germany BDSG

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.